Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 155

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Dutch halt state intervention at Chinese-owned chipmaker Nexperia, paving way for exports to resume
Europe has rare earths but, for now, it's at China's mercy like everyone else
Trump administration takes further steps to dismantle Department of Education
Trump, Saudi Crown Prince bin Salman brush off criticism of Khashoggi killing
Jim Cramer's top 10 things to watch in the stock market Wednesday
Trump calls for ABC's license to be revoked after reporter asks about Jeffrey Epstein files
Don't pass up 'free money' during open enrollment, says benefits expert—how to choose FSA and HSA contributions
Klimt painting sells for record $236 million, reviving hopes for the art market
TJ Maxx and Marshalls owner hikes outlook as CEO says holiday season is off to a 'strong start'
Target cuts profit outlook as shoppers look for deals, make fewer store trips